PT-2026-60949 · Surrealdb · Surrealdb

·

CVE-2024-58369

·

Published

2024-01-18

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.1.1
Description Authorized clients can cause a server panic leading to a denial of service by invoking custom parameters and functions at root or namespace levels. This occurs because the server fails to properly validate these invocations at unsupported levels.
Recommendations Update SurrealDB to version 1.1.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58369
GHSA-JM4V-58R5-66HJ

Affected Products

Surrealdb